The other branch supplied concrete offsets: for 3506e972 its face record 0 and its plane normal both begin at 0x1c700, and my chunk + offset_at_0x78 + 16 gives 0x1c700. Same bytes, different bookkeeping -- so the n.p+d result stands unchanged and was never in dispute. The base is chunk+0x10, on evidence with power: the loader does addi r3,r31,16; at +0x10 the six POF0-relocated slots land exactly on 0x70-0x84, the six section pointers, whereas at +0 they would relocate the u16 counts and leave two section pointers unrelocated, which is non-functional; and section-0 record 0 reads as a bbox corner at +0x10 and garbage at +0. So my '13467/13467 points inside the bbox' was vacuous. Only 11 of 13467 read as denormal at the wrong base -- the rest were still plausible coordinates, because a 16-byte shift inside a packed array of f32 triples yields other floats from the same array. Recorded the general form: a containment test cannot detect a shift inside a homogeneous array, because the shifted values come from the same distribution. For that class of error it is not a weak check, it is no check. 'Section 0 is a point list' happens to be right; the evidence I gave for it was not evidence.